Install RNA Virtual Scanner Appliance
The virtual scanner can be installed on any computer (host) with the required resources. The virtual scanner is intended to be hosted on a client’s VMware, Hyper-V or VirtualBox virtualization platform. Amazon Web Services (AWS) AMI is also supported.
Install and activate the RNA virtual scanner appliance by performing the following steps (see below for detailed instructions):
- Download the RNA virtual scanner appliance.
- Deploy the virtual scanner on your virtualization environment.
- Configure your network RNA profile for a static IP (if necessary).
- Activate the virtual scanner appliance.
Host System Requirements
This section describes the requirements necessary to host the RNA virtual scanner appliance image.
Supported Virtualization Platforms
Host Operating System | Version | Virtualization Platform (Hypervisor) | Virtual Scanner Appliance File | ||
---|---|---|---|---|---|
Windows Server | 2012 and later | Hyper-V Role | Microsoft Hyper-V (VHDX) | ||
VMware ESXi Server | 5.0 and later |
Native |
VMware ESXi (OVA) | ||
Windows Desktop / Laptop | 8.1 and later |
|
VMware ESXi (OVA) | ||
macOS | Big Sur and later |
|
VMware ESXi (OVA) | ||
Linux Ubuntu | 20.04 Desktop | Oracle VirtualBox 4.3 and later | VMware ESXi (OVA) |
Minimum Hardware Requirements
Component | Requirement |
---|---|
VM Hardware Version |
VMware Virtual Machine Hardware Version 7.0 or Later
|
CPU | Intel or AMD x86 processors, 2 or 4 CPUs, 2 GHz or higher |
Memory | 4 GB RAM (Minimum) |
Hard Disk | 60 GB free space |
BIOS Virtualization Technology |
BIOS Virtualization Technology must be enabled. By default, this setting is not enabled on most laptops. |
Peer Images | Other VMware, Hyper-V or VirtualBox images may run alongside the RNA on the host system as long as two processors, 2GB of RAM, and 10Mbps of bandwidth are available to the RNA at all times. |
Network Location |
For optimal results, the virtual scanner should be hosted on a computer near the internet gateway (the router with one side connected to your private network, and the other side connected to the internet). To protect from outside access, the host should be located on the protected side of the perimeter security device (a network component that monitors ports and accepts or rejects communications through those ports). TIP: It is recommended that the virtual scanner be hosted on a machine in a controlled access location due to the sensitivity of the data collected.
|
Physical Connections & Ports |
Host system network configuration should be a Cat 5 or above network cable with a network connection speed (throughput) of 100 MB or above. The Virtual Scanner establishes a secure connection with the Fortra Secure Network Operation Center (SNOC) over Port 443 (HTTPS) or Port 22 (SSH), which allows internal testing on your network. |
Other considerations for macOS: The virtual machine’s available bandwidth is limited by default. If this limitation is exceeded upon initiating a scan, a dialog box displays requesting permission to grant more bandwidth throughput to the virtual machine. Accept the request for the virtual scanner to function optimally.
Download RNA
The following instructions describe how to download the RNA virtual scanner appliance file.
To download the virtual scanner appliance:
- Open Fortra VM.
- From the navigation menu, select Scan Settings > Scanners.
- Select the Appliance Tokens tab.
- Under Virtual Scanners Download select the appropriate file type:
- OVA image for VMware or VirtualBox
- Hyper-V image for Windows Server Hyper-V role
- AMI for Amazon Web Services (AWS). This download will redirect to the AWS Marketplace to subscribe to the AMI and add to your AWS account.
- Save the VHDX or OVA file to your local drive.
Deploy RNA
The following instructions describe how to deploy the RNA virtual scanner appliance on your virtualization environment.
Select the applicable virtualization platform:
- Log in to your VMware ESX Server using the vSphere web client (or VMware Player, Workstation, or Fusion application).
- From the vSphere client window, select File > Deploy OVF Template.
- On the Source screen, browse to the downloaded FrontlineVirtualRNA.ova file. Select Next.
- On the OVF Template Details screen, select Next.
- On the Name and Location screen, create a unique name for the scanner (optional). If applicable, select the folder location or data-center for the virtual scanner. Select Next.
- If applicable, on the Host / Cluster screen choose the host or cluster for the virtual scanner. Select Next.
- If applicable, on the Specific Host screen choose the specific host for the virtual scanner. Select Next.
- On the Storage screen, select where to store the files for the deployed virtual scanner. Select Next.
- On the Disk Format screen, select the required format for virtual machines. Select Next.
- On the Network Mapping screen, choose the destination network to be scanned. Select Next.
- On the Ready to Complete screen, select Finish.
- On the vSphere client window, right-click the virtual scanner on the left panel, and select Power > Power On.
- Right-click the scanner again, and select Open Console.
If the vSphere Client is connected directly to an ESX/ESXi host the option to select the folder location does not appear. If connected directly to a ESX/ESXi host, skip to the Storage screen.
In order to be scanned, the chosen host or cluster must have access to the network.
This page appears only if the destination is a resource pool associated with a cluster with DRS disabled or in manual mode. If not applicable, skip to the Storage screen.
Thin provisioning lets you create sparse files with blocks that are allocated upon first access, which allows the datastore to be over-provisioned. The sparse files can continue growing and fill the datastore. If the datastore runs out of disk space while the virtual scanner is running, it can cause the virtual scanner to stop functioning.
The RNA virtual scanner appliance will boot into a console. The scanner may take a few minutes to start.
If Dynamic Host Configuration Protocol (DHCP) is in use on the network, the scanner should automatically connect to the network and the System Status: RNA Link field will indicate the scanner status. Online displays after the RNA is successfully activated and able to connect with Fortra VM, prior to successful activation the status will display as Offline. See the Internet Link field to determine general internet connectivity. If the virtual scanner is unable to use DHCP to connect, create a static IP network profile.
- Double-click the downloaded FrontlineVirtualRNA.ova file to open it.
- The first time this file is invoked, an Import Virtual Appliance window displays. Click Import.
The FrontlineVirtualRNA scanner will appear, powered off, in the left pane of the Oracle VM VirtualBox Manager. - Select the virtual scanner and click Start to power it on. The RNA virtual scanner appliance will boot into a console. The scanner may take a few minutes to start.
- Click on the new VM and go to Settings > System. Under the Extended Features section, ensure the check box for Enable EFI (special OSes only) is checked. Two banner messages will display regarding keyboard and mouse integration. Dismiss these messages by clicking the .
- First attempt to cycle through different ttys. The GUI is typically on ttys2, use CTRL + ALT+ F2 if the login prompt is on tty1.
- If that isn't successful, power off the VM and navigate to Settings > Display . Under the Graphics Controller, VBoxVGA is likely selected by default. Change the selection to VMSVGA and power on the RNA to see if the RNA GUI is brought up. If not, power off the RNA and try VBoxSVGA, power it on and see if the issue of the GUI display is resolved.
If the VM displays an error reading " FATAL: No bootable medium found! System halted.", you must click on the new VM and navigate to Settings > System. Under the Extended Features section, ensure the check box for Enable EFI (special OSes only) is checked.
If the RNA starts up and displays a login prompt instead of the standard RNA interface, perform the following:
- Click within the virtual scanner display in order to activate mouse capturing. Select Capture.
If Dynamic Host Configuration Protocol (DHCP) is in use on the network, the scanner should automatically connect to the network and the System Status: RNA Link field will indicate the scanner status. Online displays after the RNA is successfully activated and able to connect with Fortra VM, prior to successful activation the status will display as Offline. See the Internet Link field to determine general internet connectivity. If the virtual scanner is unable to use DHCP to connect, create a static IP network profile.
- Log in to your Hyper-V Server and start the Hyper-V Manager.
- From the Actions panel, select New > Virtual Machine.
- Choose a name for your virtual machine (e.g., FrontlineVirtualRNA). Select Next.
- Choose Generation 1 for the virtual machine generation. Select Next.
- Enter 4096 MB for Start up memory. Select Next.
- Select the host network adapter (virtual switch) to be used by the virtual scanner to access the network. Select Next.
- Select Use an existing virtual hard disk and browse to the VHDX file. Select Next.
- Then select Finish.
- Select the virtual machine.
- On the Action panel, select Start. Then choose Connect.
The RNA virtual scanner appliance will boot into a console. The scanner may take a few minutes to start.
- Click within the virtual scanner display in order to activate mouse capturing.
- Select Capture.
Configure Network Profile
The following instructions describe how to configure the virtual scanner to use a static IP.
Configure The Virtual Scanner To Use A Static IP as indicated by the System Status: Internet Link field:
- From the RNA console, click Edit under Network Status.
- From the drop-down, select Static.
- Enter the following information. Check with your tech support for this information.
- IP Address: The IP address for the virtual scanner
- Netmask: The subnet mask for the virtual scanner
- Gateway: The IP address for the gateway device available to the virtual scanner
- DNS Server: The IP address for the DNS server available to the virtual scanner
- Click Save.
The virtual scanner should now connect to the network, as indicated by the System Status: RNA Link field. Verify the virtual scanner's connectivity using the "status" command because it is more exhaustive than the Online / Offline field after an IP change.
Activate RNA
To activate your virtual scanner:
- Once the scanner has network access, leave the RNA virtual scanner appliance console running.
- Open the Fortra VM web interface.
- From the Fortra VM navigation menu, select Scan Settings > Scanners.
- Select the Appliance Tokens tab. The Appliance Tokens page will indicate the total number of activations available.
- Select New Token to generate a new activation token.
- On the RNA virtual scanner appliance console, enter the token in the Please enter your activation key field.
- Select Activate RNA.
- Once activated, you will see the message, "Activation Successful: This device is ready to use." You are now ready to run your first scan.
See related: Create and Run Scans.
Refer to RNA Troubleshooting for additional guidance and support.
For information regarding connectivity issues and troubleshooting, see RNA Troubleshooting